Critical Cisco SD-WAN Vulnerability Exploited by Sophisticated Threat Actor
A highly sophisticated threat actor, tracked as UAT-8616, is actively exploiting a maximum-severity vulnerability in Cisco Catalyst SD-WAN Controllers. Rapid7 disclosed CVE-2026-20182, an authentication bypass flaw rated 10.0 on the CVSS scale, which allows unauthenticated attackers to gain administrative control over network infrastructure. This marks the second time this year that a CVSS 10.0 vulnerability in Cisco's network control system has been leveraged in the wild. Following the patching of a similar earlier bug, CVE-2026-20127, the same actor quickly adapted to exploit this new weakness involving cloud deployment hub routers. Cisco Talos researchers observed the group performing post-compromise actions such as adding SSH keys, modifying NETCONF configurations, and escalating privileges to root access. Experts warn that because SD-WAN controllers sit at the center of organizational trust relationships, they are prime targets for espionage, particularly by nation-states aiming to establish persistent footholds in critical infrastructure sectors. The rapid exploitation highlights the ongoing challenges in securing central network infrastructure against advanced persistent threats.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection